Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26832
Total
1978
Critical
8053
High
8297
Medium
CVE ID Severity Score Description Published
CVE-2026-50223 HIGH 8.8 Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection … Jun 10, 2026
CVE-2026-49219 MEDIUM 5.5 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename … Jun 10, 2026
CVE-2026-49218 HIGH 7.5 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM … Jun 10, 2026
CVE-2026-48994 MEDIUM 5.9 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return … Jun 10, 2026
CVE-2026-48734 MEDIUM 5.5 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result … Jun 10, 2026
CVE-2026-48733 MEDIUM 4.7 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search … Jun 10, 2026
CVE-2026-48724 MEDIUM 5.5 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg … Jun 10, 2026
CVE-2026-47734 MEDIUM 5.7 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push … Jun 10, 2026
CVE-2026-47712 LOW 3.3 Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) derives each patch … Jun 10, 2026
CVE-2026-47342 UNKNOWN A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are … Jun 10, 2026
CVE-2026-47213 MEDIUM 6.5 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In … Jun 10, 2026
CVE-2026-47166 MEDIUM 5.7 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to … Jun 10, 2026
CVE-2026-47165 MEDIUM 4.1 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, the distributed pixel cache was originally … Jun 10, 2026
CVE-2026-46703 CRITICAL 9.6 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior … Jun 10, 2026
CVE-2026-46695 CRITICAL 10.0 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior … Jun 10, 2026
CVE-2026-46693 MEDIUM 4.1 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to … Jun 10, 2026
CVE-2026-46692 MEDIUM 4.1 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an attacker who can connect to … Jun 10, 2026
CVE-2026-46645 MEDIUM 4.3 SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that … Jun 10, 2026
CVE-2026-46559 MEDIUM 4.0 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 … Jun 10, 2026
CVE-2026-46557 MEDIUM 6.2 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack … Jun 10, 2026
CVE-2026-46521 MEDIUM 5.5 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the … Jun 10, 2026
CVE-2026-44693 HIGH 8.8 Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability … Jun 10, 2026
CVE-2026-42568 MEDIUM 4.3 Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username … Jun 10, 2026
CVE-2026-42563 UNKNOWN Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the … Jun 10, 2026
CVE-2026-42558 HIGH 7.6 Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain … Jun 10, 2026